US2007203850A1PendingUtilityA1

Multifactor authentication system

Assignee: SAPPHIRE MOBILE SYSTEMS INCPriority: Feb 15, 2006Filed: Feb 14, 2007Published: Aug 30, 2007
Est. expiryFeb 15, 2026(expired)· nominal 20-yr term from priority
G06Q 20/327G07F 7/1075G06Q 20/347G07F 7/1025G06Q 20/3674G07F 19/207G07F 7/10G07F 7/1008
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are provided to allow for multifactor authentication of automatic teller machines (ATM) transactions and transactions at a merchant's point of sale. In an illustrative implementation, a secondary PIN request is delivered to participating users, and/or a one-time use, randomly generated secondary PIN to a customer's mobile phone via a text message when the customer initiates a transaction at an ATM. The customer then replies with a text message to the secondary PIN request with the customer's PIN or inputs the secondary PIN into the ATM before the transaction may proceed. In an illustrative implementation, the customer's mobile phone is allowed to be used as a mobile PIN terminal for various payments devices used at a merchant's point of sale system. Also, an additional level of customer authentication using the ubiquitous mobile phone can be allowed, thereby increasing the security of ATM transactions and non-cash payments.

Claims

exact text as granted — not AI-modified
1 . A system for authenticating the identity of a user attempting a financial transaction comprising:
 a multifactor authentication engine; and   an instruction set operable to provide at least one instruction to the multifactor authentication engine to process electronic data according to a selected multifactor authentication paradigm,
 wherein the multifactor authentication paradigm comprises the verification of a mobile communications device and the verification of a personal identification number or code delivered using the mobile communications device. 
   
     
     
         2 . The system as recited in  claim 1  wherein multifactor authentication engine comprises a computing environment. 
     
     
         3 . The system as recited in  claim 2  wherein the instruction set comprises a computing application operable on a computing environment. 
     
     
         4 . The system as recited in  claim 3  further comprising a data store cooperating with the multifactor authentication engine to verify a mobile communications device and a personal identification number or code delivered using the mobile communications device. 
     
     
         5 . The system as recited in  claim 4  further comprising one or more communications networks selected from the following group: a fixed wire network, a wireless network, a mobile communications network, a debit network, a credit network, a network used for processing electronic payments and the Internet. 
     
     
         6 . The system as recited in  claim 1  wherein the multifactor authentication engine is operated by a payments processor, a financial institution, a credit reporting agency or by an entity which has contracted with a payments processor, a financial institution or a credit reporting agency. 
     
     
         7 . A method for authenticating the identity of a user attempting a financial transaction comprising:
 receiving a submitted first data set from a user attempting a financial transaction;   authenticating the submitted first data set against a known first data set, wherein the known first data set contains information associated with the user, rejecting the financial transaction should the authentication of the submitted first data set fail;   submitting a request for a second data set to the user;   receiving a submitted second data set from the user;   authenticating the submitted second data set against a known second data set, wherein the known second data set contains information associated with the user, rejecting the financial transaction should the authentication of the submitted second data set fail; and   allowing the financial transaction to proceed should the submitted first data set and the submitted second data be properly authenticated.   
     
     
         8 . The method as recited in  claim 7  in which the financial transaction comprises any of a transaction undertaken at an automated teller machine, accessing a user account through an online banking portal, a transaction undertaken at a point of sale system, and a transaction undertaken with a credit reporting agency. 
     
     
         9 . The method as recited in  claim 7  in which the submitted first data set is delivered an instrumentality comprising any of a credit card, a debit card, a barcode, a magnetic stripe, a near-field communications device, a radio frequency identification device, an Internet webpage, and by the submission of user-identification data known to a credit reporting agency. 
     
     
         10 . The method as recited in  claim 7  in which the request for a second data set is submitted to the user using one or more instrumentalities comprising a text message delivered by the short message service and a multimedia message delivered by the multimedia message service. 
     
     
         11 . The method as recited in  claim 7  in which the submitted second data set is submitted by the user using one or more instrumentalities comprising a text message delivered by the short message service, a multimedia message delivered by the multimedia message service, and as a one-time use personal identification number inputted into an automated teller machine or a point of sale device. 
     
     
         12 . The method as recited in  claim 7  in which the submitted second data set comprises a personal identification number. 
     
     
         13 . The method as recited in  claim 7  in which the submitted second data set comprises data identifying the user's mobile phone. 
     
     
         14 . A computer readable medium having computer readable instructions to instruct a computer to perform a method for authenticating the identity of a user attempting a financial transaction comprising:
 receiving a submitted first data set from a user attempting a financial transaction;   authenticating the submitted first data set against a known first data set, wherein the known first data set contains information associated with the user, rejecting the financial transaction should the authentication of the submitted first data set fail;   submitting a request for a second data set to the user;   receiving a submitted second data set from the user;   authenticating the submitted second data set against a known second data set, wherein the known second data set contains information associated with the user, rejecting the financial transaction should the authentication of the submitted second data set fail; and   allowing the financial transaction to proceed should the submitted first data set and the submitted second data be properly authenticated.   
     
     
         15 . The computer readable medium as recited in  claim 14  in which the financial transaction is a transaction comprises any of a transaction undertaken at an automated teller machine, accessing a user account through an online banking portal, a transaction undertaken at a point of sale system, and a transaction undertaken with a credit reporting agency. 
     
     
         16 . The computer readable medium as recited in  claim 14  in which the submitted first data set is delivered by one or more instrumentalities comprising a credit card, a debit card, a barcode, a magnetic stripe, a near-field communications device, a radio frequency identification device, an Internet webpage, and the submission of user-identification data known to a credit reporting agency. 
     
     
         17 . The computer readable medium as recited in  claim 14  in which the request for a second data set is submitted to the user using one or more instrumentalities comprising a text message delivered by the short message service, and a multimedia message delivered by the multimedia message service. 
     
     
         18 . The computer readable medium as recited in  claim 14  in which the submitted second data set is submitted by the user using one or more instrumentalities comprising a text message delivered by the short message service, a multimedia message delivered by the multimedia message service, and a one-time use personal identification number inputted into an automated teller machine or a point of sale device. 
     
     
         19 . The computer readable medium as recited in  claim 14  in which the submitted second data set comprises a personal identification number. 
     
     
         20 . The computer readable medium as recited in  claim 14  in which the submitted second data set comprises data identifying the user's mobile phone.

Join the waitlist — get patent alerts

Track US2007203850A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.